Description
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*.
Published: 2026-09-22
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Potential remote code execution via heap-based buffer overflow
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer overflow in the core libraries of RTI Connext Professional allows an attacker to overwrite adjacent memory, potentially leading to arbitrary code execution or denial of service. The flaw is classified as CWE-122 and can compromise confidentiality, integrity, and availability if exploited.

Affected Systems

The vulnerability affects RTI Connext Professional from version 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, and from 5.2.3 before 5.2.*.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, but no EPSS score is available, leaving the exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog, so a known exploit is not confirmed. Based on the description, it is inferred that the attack likely occurs over the network through malformed DDS packets sent to the Connext middleware, requiring the target to be reachable from the threat actor's network. The impact could be full compromise of the affected system if an attacker can successfully send crafted data.

Generated by OpenCVE AI on September 22, 2026 at 19:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a non‑affected version of RTI Connext Professional (at least 7.7.0.1, 7.3.1.6, 6.1.*, 6.0.*, 5.3.*, or 5.2.*).
  • If a patch or upgrade is not immediately possible, restrict network access to Connext services by configuring firewalls or access controls to only allow trusted hosts.
  • Continuously monitor DDS traffic and system logs for abnormal or malformed messages that may indicate an attempted exploitation.

Generated by OpenCVE AI on September 22, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.3 before 5.2.*.
Title Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers.
First Time appeared Rti
Rti connext Professional
Weaknesses CWE-122
CPEs cpe:2.3:a:rti:connext_professional:*:*:*:*:*:*:*:*
Vendors & Products Rti
Rti connext Professional
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rti Connext Professional
cve-icon MITRE

Status: PUBLISHED

Assigner: RTI

Published:

Updated: 2026-09-22T18:48:54.400Z

Reserved: 2026-07-31T07:28:25.781Z

Link: CVE-2026-18457

cve-icon Vulnrichment

Updated: 2026-09-22T18:48:51.144Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T18:17:11.487

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-18457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:15:09Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow